openEuler 24.03 LTS update for exiv2



Risk Low
Patch available YES
Number of vulnerabilities 14
CVE-ID CVE-2024-39695
CVE-2016-5479
CVE-2016-5621
CVE-2016-5603
CVE-2016-5594
CVE-2016-5490
CVE-2016-5493
CVE-2016-5620
CVE-2016-5502
CVE-2016-5569
CVE-2016-5543
CVE-2016-5619
CVE-2016-5622
CVE-2016-5607
CWE-ID CWE-125
CWE-399
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
openEuler
Operating systems & Components / Operating system

exiv2-help
Operating systems & Components / Operating system package or component

exiv2-devel
Operating systems & Components / Operating system package or component

exiv2-debugsource
Operating systems & Components / Operating system package or component

exiv2-debuginfo
Operating systems & Components / Operating system package or component

exiv2
Operating systems & Components / Operating system package or component

Vendor openEuler

Security Bulletin

This security bulletin contains information about 14 vulnerabilities.

1) Out-of-bounds read

EUVDB-ID: #VU93855

Risk: Low

CVSSv3.1: 3.8 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2024-39695

CWE-ID: CWE-125 - Out-of-bounds read

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary condition in the parser for the ASF video format in AsfVideo::streamProperties(). A remote attacker can pass a specially crafted media file to the application, trigger an out-of-bounds read error and perform a denial of service (DoS) attack.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

openEuler: 24.03 LTS

exiv2-help: before 0.28.2-2

exiv2-devel: before 0.28.2-2

exiv2-debugsource: before 0.28.2-2

exiv2-debuginfo: before 0.28.2-2

exiv2: before 0.28.2-2

CPE2.3 External links

http://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2024-1841


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Information disclosure

EUVDB-ID: #VU1061

Risk: Low

CVSSv3.1: 4.4 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2016-5479

CWE-ID: CWE-399 - Resource Management Errors

Exploit availability: No

Description

The vulnerability allows a remote authenticated user to access data on the target system.
The weakness is caused by a flaw in the Oracle FLEXCUBE Universal Banking INFRA component and lets attacker obtain arbitrary files.
Successful exploitation of the vulnerability results in disclosure of information on the vulnerable system.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

openEuler: 24.03 LTS

exiv2-help: before 0.28.2-2

exiv2-devel: before 0.28.2-2

exiv2-debugsource: before 0.28.2-2

exiv2-debuginfo: before 0.28.2-2

exiv2: before 0.28.2-2

CPE2.3 External links

http://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2024-1841


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

3) Information disclosure

EUVDB-ID: #VU1060

Risk: Low

CVSSv3.1: 4.4 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2016-5621

CWE-ID: CWE-399 - Resource Management Errors

Exploit availability: No

Description

The vulnerability allows a remote authenticated user to access data on the target system.
The weakness is caused by a flaw in the Oracle FLEXCUBE Universal Banking INFRA component and lets attacker obtain arbitrary files.
Successful exploitation of the vulnerability results in disclosure of information on the vulnerable system.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

openEuler: 24.03 LTS

exiv2-help: before 0.28.2-2

exiv2-devel: before 0.28.2-2

exiv2-debugsource: before 0.28.2-2

exiv2-debuginfo: before 0.28.2-2

exiv2: before 0.28.2-2

CPE2.3 External links

http://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2024-1841


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

4) Information disclosure

EUVDB-ID: #VU1059

Risk: Low

CVSSv3.1: 4.4 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2016-5603

CWE-ID: CWE-399 - Resource Management Errors

Exploit availability: No

Description

The vulnerability allows a remote authenticated user to access data on the target system.
The weakness is caused by a flaw in the Oracle FLEXCUBE Universal Banking INFRA component and lets attacker obtain arbitrary files.
Successful exploitation of the vulnerability results in disclosure of information on the vulnerable system.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

openEuler: 24.03 LTS

exiv2-help: before 0.28.2-2

exiv2-devel: before 0.28.2-2

exiv2-debugsource: before 0.28.2-2

exiv2-debuginfo: before 0.28.2-2

exiv2: before 0.28.2-2

CPE2.3 External links

http://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2024-1841


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

5) Information disclosure

EUVDB-ID: #VU1058

Risk: Low

CVSSv3.1: 4.4 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2016-5594

CWE-ID: CWE-399 - Resource Management Errors

Exploit availability: No

Description

The vulnerability allows a remote authenticated user to access data on the target system.
The weakness is caused by a flaw in the Oracle FLEXCUBE Universal Banking INFRA component and lets attacker obtain arbitrary files.
Successful exploitation of the vulnerability results in disclosure of information on the vulnerable system.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

openEuler: 24.03 LTS

exiv2-help: before 0.28.2-2

exiv2-devel: before 0.28.2-2

exiv2-debugsource: before 0.28.2-2

exiv2-debuginfo: before 0.28.2-2

exiv2: before 0.28.2-2

CPE2.3 External links

http://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2024-1841


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

6) Information disclosure

EUVDB-ID: #VU1057

Risk: Low

CVSSv3.1: 2.9 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2016-5490

CWE-ID: CWE-399 - Resource Management Errors

Exploit availability: No

Description

The vulnerability allows a local user to access data on the target system.
The weakness is caused by a flaw in the Oracle FLEXCUBE Universal Banking INFRA component and lets attacker  obtain arbitrary files.
Successful exploitation of the vulnerability results in disclosure of information on the vulnerable system.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

openEuler: 24.03 LTS

exiv2-help: before 0.28.2-2

exiv2-devel: before 0.28.2-2

exiv2-debugsource: before 0.28.2-2

exiv2-debuginfo: before 0.28.2-2

exiv2: before 0.28.2-2

CPE2.3 External links

http://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2024-1841


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

7) Information disclosure

EUVDB-ID: #VU1056

Risk: Low

CVSSv3.1: 3.7 [CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2016-5493

CWE-ID: CWE-399 - Resource Management Errors

Exploit availability: No

Description

The vulnerability allows a remote authenticated user to access data on the target system.
The weakness is caused by a flaw in the Oracle FLEXCUBE Private Banking Admin component and lets attacker partially obtain and partially modify arbitrary files.
Successful exploitation of the vulnerability results in disclosure and partial modification of information on the vulnerable system.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

openEuler: 24.03 LTS

exiv2-help: before 0.28.2-2

exiv2-devel: before 0.28.2-2

exiv2-debugsource: before 0.28.2-2

exiv2-debuginfo: before 0.28.2-2

exiv2: before 0.28.2-2

CPE2.3 External links

http://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2024-1841


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

8) Information disclosure

EUVDB-ID: #VU1055

Risk: Low

CVSSv3.1: 4.7 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2016-5620

CWE-ID: CWE-399 - Resource Management Errors

Exploit availability: No

Description

The vulnerability allows a remote authenticated user to access data on the target system.
The weakness is caused by a flaw in the Oracle FLEXCUBE Universal Banking INFRA componentt and lets attacker partially obtain and partially modify arbitrary files.
Successful exploitation of the vulnerability results in disclosure and partial modification of information on the vulnerable system.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

openEuler: 24.03 LTS

exiv2-help: before 0.28.2-2

exiv2-devel: before 0.28.2-2

exiv2-debugsource: before 0.28.2-2

exiv2-debuginfo: before 0.28.2-2

exiv2: before 0.28.2-2

CPE2.3 External links

http://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2024-1841


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

9) Information disclosure

EUVDB-ID: #VU1054

Risk: Low

CVSSv3.1: 4.7 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2016-5502

CWE-ID: CWE-399 - Resource Management Errors

Exploit availability: No

Description

The vulnerability allows a remote authenticated user to access data on the target system.
The weakness is caused by a flaw in the Oracle FLEXCUBE Universal Banking INFRA componentt and lets attacker partially obtain and partially modify arbitrary files.
Successful exploitation of the vulnerability results in disclosure and partial modification of information on the vulnerable system.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

openEuler: 24.03 LTS

exiv2-help: before 0.28.2-2

exiv2-devel: before 0.28.2-2

exiv2-debugsource: before 0.28.2-2

exiv2-debuginfo: before 0.28.2-2

exiv2: before 0.28.2-2

CPE2.3 External links

http://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2024-1841


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

10) Information disclosure

EUVDB-ID: #VU1053

Risk: Low

CVSSv3.1: 4.7 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2016-5569

CWE-ID: CWE-399 - Resource Management Errors

Exploit availability: No

Description

The vulnerability allows a remote authenticated user to access data on the target system.
The weakness is caused by a flaw in the Oracle FLEXCUBE Enterprise Limits and Collateral Management Limits and Collateral component and lets attacker partially obtain and partially modify arbitrary files.
Successful exploitation of the vulnerability results in disclosure and partial modification of information on the vulnerable system.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

openEuler: 24.03 LTS

exiv2-help: before 0.28.2-2

exiv2-devel: before 0.28.2-2

exiv2-debugsource: before 0.28.2-2

exiv2-debuginfo: before 0.28.2-2

exiv2: before 0.28.2-2

CPE2.3 External links

http://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2024-1841


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

11) Information disclosure

EUVDB-ID: #VU1052

Risk: Low

CVSSv3.1: 5.3 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2016-5543

CWE-ID: CWE-399 - Resource Management Errors

Exploit availability: No

Description

The vulnerability allows a remote unauthenticated user to access data on the target system.
The weakness is caused by a flaw in the Oracle FLEXCUBE Enterprise Limits and Collateral Management INFRA component and lets attacker partially obtain and partially modify arbitrary files.
Successful exploitation of the vulnerability results in disclosure and partial modification of information on the vulnerable system.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

openEuler: 24.03 LTS

exiv2-help: before 0.28.2-2

exiv2-devel: before 0.28.2-2

exiv2-debugsource: before 0.28.2-2

exiv2-debuginfo: before 0.28.2-2

exiv2: before 0.28.2-2

CPE2.3 External links

http://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2024-1841


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

12) Information disclosure

EUVDB-ID: #VU1051

Risk: Low

CVSSv3.1: 7.1 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2016-5619

CWE-ID: CWE-399 - Resource Management Errors

Exploit availability: No

Description

The vulnerability allows a remote authenticated user to access data on the target system.
The weakness is caused by a flaw in the Oracle FLEXCUBE Universal Banking INFRA component and lets attacker obtain and modify arbitrary files.
Successful exploitation of the vulnerability results in disclosure and modification of information on the vulnerable system.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

openEuler: 24.03 LTS

exiv2-help: before 0.28.2-2

exiv2-devel: before 0.28.2-2

exiv2-debugsource: before 0.28.2-2

exiv2-debuginfo: before 0.28.2-2

exiv2: before 0.28.2-2

CPE2.3 External links

http://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2024-1841


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

13) Information disclosure

EUVDB-ID: #VU1050

Risk: Low

CVSSv3.1: 5.3 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2016-5622

CWE-ID: CWE-399 - Resource Management Errors

Exploit availability: No

Description

The vulnerability allows a remote unauthenticated user to access data on the target system.
The weakness is caused by a flaw in the Oracle FLEXCUBE Universal Banking INFRA component and lets attacker obtain and partially modify arbitrary files.
Successful exploitation of the vulnerability results in disclosure and partial modification of information on the vulnerable system.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

openEuler: 24.03 LTS

exiv2-help: before 0.28.2-2

exiv2-devel: before 0.28.2-2

exiv2-debugsource: before 0.28.2-2

exiv2-debuginfo: before 0.28.2-2

exiv2: before 0.28.2-2

CPE2.3 External links

http://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2024-1841


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

14) Privilege escalation

EUVDB-ID: #VU1049

Risk: Low

CVSSv3.1: 7.7 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2016-5607

CWE-ID: CWE-399 - Resource Management Errors

Exploit availability: No

Description

The vulnerability allows a remote authenticated user to gain elevated privileges on the target system.
The weakness is caused by a flaw in the Oracle FLEXCUBE Universal Banking INFRA component and lets attacker increase his privileges.
Successful exploitation of the vulnerability results in privilege escalation on the vulnerable system.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

openEuler: 24.03 LTS

exiv2-help: before 0.28.2-2

exiv2-devel: before 0.28.2-2

exiv2-debugsource: before 0.28.2-2

exiv2-debuginfo: before 0.28.2-2

exiv2: before 0.28.2-2

CPE2.3 External links

http://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2024-1841


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###